如何使用Fiddler抓取采用HTTP CONNECT方法的手机应用?高德地图地铁客流数据抓取遇阻咨询
Can you capture Amap's subway passenger flow data via Fiddler?
Absolutely—this data is accessible via the app's API requests, but you're hitting common HTTPS decryption and configuration hurdles. Let's work through this step by step:
1. First, confirm Fiddler's HTTPS decryption is actually working
The locked CONNECT requests you see are normal—they're just the tunnels that HTTPS traffic travels through. For Fiddler to reveal the actual decrypted requests inside these tunnels, you need to:
- Open Fiddler >
Tools>Options>HTTPStab - Ensure Decrypt HTTPS traffic is checked, along with Ignore server certificate errors (unsafe) (enable this temporarily for testing)
- Critical step: Install Fiddler's root certificate on your mobile device, and manually trust it:
- For Android 7+: Go to
Settings>Security>Encryption & credentials>Install a certificate>CA certificate, then select the Fiddler cert you transferred. You’ll also need to toggle on "Trust user certificates" in your device’s security settings. - For iOS 10+: After installing the cert, go to
Settings>General>About>Certificate Trust Settingsand enable trust for the Fiddler root cert.
- For Android 7+: Go to
If you skip the certificate trust step, Fiddler can’t decrypt the HTTPS traffic inside the CONNECT tunnels, so you’ll never see the actual API requests you need.
2. Why your custom Fiddler rule didn’t work
Your script has syntax errors that prevent it from running correctly:
- You’re using Chinese quotation marks (
‘’) instead of English ones (''/"") - HTML-encoded characters like
"and&&should be replaced with raw English quotes and&&
Here’s the corrected version of your rule:
if (oSession.oRequest['User-Agent'].IndexOf("Android") > -1 && oSession.HTTPMethodIs("CONNECT")) { oSession.oResponse.headers["Connection"] = "Keep-Alive"; }
That said, this rule is probably unnecessary for your core goal. CONNECT requests are just tunnel setup—you need to focus on the actual HTTPS API requests that appear in the Fiddler session list once decryption is working.
3. If you still don’t see the API requests: Bypass SSL Pinning
Many apps (including Amap) use SSL Pinning—this means the app only trusts its own pre-approved certificates, not Fiddler’s root cert. If decryption is set up correctly but you still don’t see the traffic, you’ll need to bypass this:
- For Android: Use tools like Xposed + JustTrustMe module, or write a simple Frida script to hook and disable certificate validation.
- For iOS: Use TrustMeNot (a Cydia tweak) or a Frida script to bypass pinning.
Once pinning is bypassed, Fiddler will be able to decrypt the app’s HTTPS traffic, and you’ll find the subway passenger flow data in requests to Amap’s API endpoints (usually under domains like api.amap.com or similar).
Final Notes
The key steps are:
- Get Fiddler’s HTTPS decryption fully working with trusted certificates on your device
- Bypass SSL Pinning if the app blocks Fiddler’s cert
- Ignore the CONNECT requests themselves—look for the actual API calls that appear after the tunnel is established
内容的提问来源于stack exchange,提问作者Freddie-Hawking

